Home/Threat Actor/DragonForce
Threat Actor

DragonForce

dragonforce · malaysia_origin_with_international_affiliates · active since 2021-01

DragonForce (also DragonForce Malaysia, DragonForce Cartel) is a financially-motivated cybercriminal ransomware-as-a- service operation with operationally-distinctive evolution from pro-Palestine / anti-Israel hacktivism (2021-2023 DragonForce Malaysia operations including OpsBedil and OpsPatuk DDoS/defacement campaigns) to commercial cybercriminal RaaS (2023-2024 pivot leveraging the September 2022 leaked LockBit Black builder) and ultimately the current "DragonForce Cartel" operational framework allowing affiliates flexibility to use DragonForce-provided or affiliate-provided ransomware under DragonForce branding and infrastructure; achieved peak public visibility through April-May 2025 UK retail sector wave against Marks & Spencer, Co-op, and Harrods operationally connected to Scattered Spider operators acting as DragonForce affiliates.

operates DragonLeaks dark- web leak site for double-extortion pressure.

signature tooling includes derived-LockBit-3-ransomware variants, rclone- mediated Mega.nz data exfiltration, AnyDesk operator hands-on tooling, and VMware ESXi hypervisor targeting; operationally distinct from but ecosystem-adjacent to LockBit, Akira, Play, Black Basta, Scattered Spider, and other ransomware ecosystem actors curated separately.

malaysia_origin_with_international_affiliates confidence: high 12 aliases

Profile

DragonForce (also DragonForce Malaysia, DragonForce Cartel) is a financially-motivated cybercriminal ransomware-as-a- service (RaaS) operation with an operationally-distinctive history of evolution from hacktivism to commercial cybercriminal ransomware, an unusual operational trajectory in the modern ransomware ecosystem and one that operationally distinguishes DragonForce from purely-financially-motivated ransomware clusters with no political-ideological operational history. The cluster's operational evolution spans three distinct operational phases: (1) HACKTIVIST-ERA ORIGINS (2021-2023). The cluster was originally established as "DragonForce Malaysia", a pro- Palestine / anti-Israel hacktivist collective conducting website defacements, distributed denial-of-service (DDoS) attacks, and data leaks against Indian and Israeli government and commercial organizations under stated ideological motivations. Hacktivist-era operations included the OpsBedil campaign (anti-Israel operations) and OpsPatuk (anti-India operations). The hacktivist-era operational profile included low-sophistication tradecraft and stated ideological motivations, operationally distinct from the financially- motivated ransomware ecosystem the cluster subsequently pivoted to. (2) RAAS PIVOT VIA LEAKED LOCKBIT BUILDER (2023-2024). Following the September 2022 leak of the LockBit Black (LockBit 3.0) ransomware builder, DragonForce operators leveraged the leaked builder as the initial technical foundation for an operational pivot to a ransomware-as-a- service commercial model. The leveraged-LockBit-builder approach allowed rapid RaaS establishment with proven encryption tooling, and DragonForce subsequently developed proprietary ransomware variants beyond the LockBit-derivative foundation. The RaaS pivot transformed the cluster's operational priorities from ideologically-motivated to financially-motivated, though residual ideological- targeting patterns (continued Israeli and Indian victim targeting at elevated rates relative to base affiliate targeting profiles) have persisted in cluster operations. (3) DRAGONFORCE CARTEL OPERATIONAL FRAMEWORK (2024-PRESENT). The cluster's current operational structure is the "DragonForce Cartel", a self-styled RaaS affiliate framework with operationally-distinctive flexibility allowing affiliates the option to use DragonForce-provided ransomware OR affiliate-provided ransomware under DragonForce branding, negotiation infrastructure, and leak-site infrastructure. The Cartel framework is operationally innovative within the ransomware ecosystem, moving beyond traditional RaaS models (where affiliates use the operator's ransomware exclusively) toward an infrastructure-as-a-service model where DragonForce provides the operational backbone. The Cartel framework attracted affiliate interest from operators displaced by the disruption of major RaaS operations including LockBit (Operation Cronos February 2024) and ALPHV / BlackCat (collapse / exit-scam March 2024). The cluster's operational profile achieved peak public visibility in April-May 2025 through a high-profile wave of attacks against major UK retailers (Marks & Spencer, Co-op, Harrods). The UK retail wave was operationally connected to Scattered Spider (scattered_spider.yaml) operators acting as DragonForce affiliates, operationally consistent with the Cartel affiliate-flexibility model where Scattered Spider operators leveraged their signature social-engineering initial-access tradecraft for the intrusion phase while using DragonForce's RaaS infrastructure for the ransomware deployment phase. The Marks & Spencer attack (April 2025) resulted in operational disruption lasting weeks including online ordering shutdown and supply-chain disruption.

the Co-op attack resulted in significant employee data theft. The UK retail wave significantly raised DragonForce's operational profile and established the cluster as one of the most operationally significant ransomware operations of 2025. The cluster's operational tooling toolkit is affiliate- dependent (as is typical for RaaS operations) but consistent operational patterns include rclone-mediated data exfiltration to cloud storage (Mega.nz, Backblaze), VMware ESXi hypervisor targeting for mass-encryption deployment, AnyDesk and ConnectWise ScreenConnect for operator hands-on activity, and double-extortion pressure via DragonLeaks leak-site data publication. DragonForce is curated alongside the broader ransomware ecosystem coverage in this corpus (LockBit, Akira, Play, Black Basta, Royal / BlackSuit, Cactus, Rhysida, INC Ransom, Medusa, Qilin, Hunters International, BianLian, RansomHub, Fog, Embargo, NoEscape, Trigona, Hive, REvil, DarkSide / BlackMatter, ALPHV / BlackCat, Maze, Conti / Wizard Spider, Cuba, Vice Society / Vanilla Tempest, Trigona). Its operational distinctiveness within this ecosystem is the hacktivism-to-RaaS evolutionary trajectory and the operational innovation of the Cartel affiliate-flexibility framework.

Aliases

12
dragonforcedragonforce ransomwaredragonforce raasdragonforce_malaysiadragonforce malaysiadragonforce carteldragonforce ransomware carteldragonforce affiliate clusterdragonforce operatorsdragonleaksdragon_forcedragon force

Notable Campaigns

5
2025UK Retail Sector Wave, Marks & Spencer, Co-op, Harrods (April-May 2025)
2024DragonForce Cartel RaaS Affiliate Framework (2024)
2023-2025DragonLeaks Leak Site Operations and Double-Extortion Pattern
2023RaaS Pivot via Leveraging Leaked LockBit Black Builder (2023)
2021-2023DragonForce Malaysia Hacktivist-Era Operations (2021-2023)

Attribution & Reporting

Attributed by
SentinelOneHalcyonCyberIntGroup-IBCyfirmaSophosSOCRadarRecorded FutureBridewell ConsultingTrend MicroCrowdStrikeMandiant (Google Threat Intelligence)UK National Crime Agency (NCA)UK National Cyber Security Centre (NCSC)Malaysian CyberSecurity Malaysia (CSM)Israeli National Cyber Directorate (INCD)
Key reporting
reportSentinelOne: DragonForce Malaysia, From Hacktivism to Ransomware (2023)
reportHalcyon: DragonForce Ransomware Threat Intelligence Profile
reportGroup-IB: DragonForce RaaS Operational Analysis
reportBridewell Consulting: UK Retail DragonForce Attacks 2025, Threat Intelligence Assessment
reportSOCRadar: DragonForce Dark Web Profile
reportCyfirma: DragonForce Ransomware Technical Analysis
reportUK National Crime Agency (NCA): DragonForce Ransomware Advisory
reportMandiant / Google Threat Intelligence: DragonForce / Scattered Spider UK Retail Wave Analysis
reportMalpedia Actor Profile: DragonForce

Operational

State sponsor

DragonForce is a financially-motivated cybercriminal ransomware-as-a-service (RaaS) operation with an operationally- distinctive history of evolution from hacktivism to commercial cybercriminal ransomware. The cluster was originally established as "DragonForce Malaysia" in 2021 as a pro- Palestine / anti-Israel hacktivist collective conducting website defacements, distributed denial-of-service attacks, and data leaks against Indian and Israeli government and commercial organizations, operating with stated ideological motivations rather than financial ones. During 2023-2024, the cluster pivoted operationally to a ransomware-as-a-service commercial model, building affiliate-driven ransomware operations on initial encryption tooling derived from the September 2022 leaked LockBit Black (LockBit 3.0) ransomware builder.

The cluster has subsequently developed its own ransomware variants and operates the "DragonForce Cartel", a self-styled RaaS affiliate framework allowing affiliates operational flexibility (including the option to use DragonForce-provided ransomware OR affiliate-provided ransomware under the DragonForce branding and leak-site infrastructure). The cluster's operational origin is assessed with high confidence as Malaysian based on the DragonForce Malaysia hacktivist-era operational history, forum-post linguistic analysis, and operational tradecraft indicators, but the current RaaS-era operations involve international affiliates with operational connections to the broader Russian-language and English-language cybercriminal ransomware ecosystems. The cluster is not assessed by industry analysis as having state sponsorship, though the hacktivist-era origin and anti-Israel ideological alignment operationally distinguish it from purely-financially- motivated ransomware clusters with no political-ideological operational history.

Motivations
financial_gain, ransomware_extortion, double_and_triple_extortion_operations, hacktivism_residual_ideological_component, anti_israel_anti_india_ideological_targeting_residual, ransomware_affiliate_revenue_sharing
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)31/60 · 51%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)17/60 · 28%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MEGASYNCMETASPLOITSOFTPERFECT NETWORK SCANNERSPLASHTOP
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin